Expert Advice Community

Guest

ISO 27018 versions

  Quote
Guest
Guest user Created:   Feb 14, 2020 Last commented:   Mar 05, 2020

ISO 27018 versions

What's the difference between ISO 27018:2014 and ISO 27018:2019?

0 0

Assign topic to the user

ISO 22301 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 22301 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Feb 14, 2020

ISO 27018:2019 has introduced only minor changes and corrections, which do not impact controls application:

  • It makes clearer that ISO 27018 is not a certifiable standard, but supports the application of ISO 27001, which is the certifiable standard 
  • change in the use of verbs (e.g., "may" and "can") to simplify the presentation of what an organization can be responsible for
  • addition of a "General" section at the beginning of the Public Cloud Processor Extended Control Set for PII Protection (this new section does not add new controls).

In short, these issues do not require immediate changes for those which applies these controls.

Quote
0 1
Guest
Gabriella De Blasi Feb 14, 2020

Thank you very much.

Quote
0 0
Raúl Mar 04, 2020

Hi Leat, can you give me some guidance, please. AWS, Google and so on are certified in this standard ISO/IEC 27018:2019, by E&Y, BSI etc. How they are doing this?

Quote
0 0
Expert
Rhand Leal Mar 05, 2020

Please note that ISO 27018 is not a certifiable standard. What happens, depending on the hired certification body, is that it "certifies" against ISO 27018 during an ISO 27001 certification process, because ISO 27001 is the only certifiable standard in the ISO 27000 series. The certification body includes in the certification a statement that the organization is also compliant with ISO 27018. The surveillance audits will be the same as for a normal ISO 27001 certification, normally one each year.

These articles can provide further information:

Quote
0 1
Raúl Mar 05, 2020

Thans

Regards

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Feb 14, 2020

Mar 05, 2020

Suggested Topics

Guest user Created:   May 25, 2023 ISO 27001 & 22301
Replies: 1
0 0

Privacy Policy Template

Ash Created:   Jan 21, 2024 ISO 27001 & 22301
Replies: 1
0 1

ISO 27001 Internal Audits